
LifterLMS <= 3.34.5 - Import d'options non authentifié
LifterLMS <= 3.34.5 - Import des options non authentifié
Import des options non authentifié, ce qui pourrait conduire à :
Redirection du site web
Création de compte administrateur
Injection de contenu
XSS stocké
Les problèmes ont été signalés comme corrigés dans la version 3.35.0. Cependant, la version 3.35.1 a ajouté une validation et un filtrage supplémentaires des entrées.
$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email [email protected] LifterLMS <= 3.34.5 - Import des options non authentifié Exploit par Ramdom Robbie Une fois exécuté, vérifiez votre courriel pour le lien de mot de passe oublié. E-mail de réinitialisation de mot de passe envoyé à [email protected]
Requires access to login.php and working email address and the site needs to be able to send emails